drjobs Information Security Compliance Engineer

Information Security Compliance Engineer

Employer Active

1 Vacancy
The job posting is outdated and position may be filled
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Jobs by Experience drjobs

5-7years

Job Location drjobs

Herndon, VA - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

This is a remote position.

Title: Information Security & Compliance Engineer
Location: Herndon VA or Remote from: VA MD DC PA IL NJ NC SC GA FL TX WA
Terms: FullTime/Permanent
Work Authorization: Due to federal regulations all qualified applicants must be US Citizens.

We are seeking a technical compliance engineer with a strong Information Security background. This person should have strong experience conducting assessments and determining levels of risk as well as understanding coordinating ways to mitigate said risk. This is a highfunctioning team that helps deliver extermely important SAAS solutions to our customers.


Responsibilities:
  • Conduct risk assessments and threat modeling implement and coordinate actionable reduction tactics to address issues and mitigate risks and oversee risk remediation efforts.
  • Engage with engineers from infrastructure and development teams to provide technical guidance for security requirements architecture design and development practices.
  • Provide engineering support for controls to comply with NIST SP800171 NIST SP80053 and ISO 27001/2 requirements.
  • Write control descriptions based on current architecture and propose remediation actions at the technical operational level.
  • Create and update the organization s information security policies standards procedures and guidelines.
  • Evaluate emerging trends and technology and work with technical teams to understand and prepare for a potential impact to the organization s information security posture.


Requirements

Basic Qualifications:
  • 7 years of demonstrated IT Security engineering work experience providing guidance to project teams.
  • 5 years of demonstrated TCP/IP network engineering and administration experience.
  • 5 years of demonstrated Windows / Linux system engineering and administration experience.
  • Demonstrated experience working with secureSDLC practices in a commercial environment utilizing agile and DevOps models.
  • Demonstrated experience in implementing and maintaining security controls in onpremise and cloud environments.
  • Demonstrated experience performing risk assessments and threat modeling.
  • Demonstrated experience in writing System Security Plans and POAMs.
  • Significant experience in working with ISO 27001/2 NIST 800171 and NIST 80053.
  • Demonstrated ability to understand and respond to complex business requirements.
  • Demonstrated ability in strong verbal and written communication skills to interface with technical and business stakeholders.
  • Significant experience working in Jira and Confluence.
  • Be able to pass background investigation to attain and maintain Trusted Role access to company systems.
  • Experience / familiarity with these networking technologies:
    • Key network services including HTTP/SMTP/DNS and supporting technologies including web domain and mail servers
    • Encryption (IPSec/SSL/TLS)
    • Network Security (e.g. Firewalls Network Access Controls Proxies SPAM/Phishing Prevention etc)

Preferred Qualifications:

  • CISSP and other technical certifications are a plus.
  • Experience with Governance Risk and Compliance tools.
  • Cloud computing and architecture.
  • Windows Domains and Active Directory.
  • Endpoint Protections (HIPS/HIDS).
  • Web Application Programming (Java and related technologies).
  • Knowledge and demonstrated experience designing multitier highly available multithreaded scalable architectures.
  • Secure development frameworks (e.g. OWASP SAMM Microsoft Security Development Lifecycle IBM Secure Engineering Framework etc.)
  • Public Key Infrastructure (PKI)
  • Identity Federation Technologies (SAML etc.)
  • Business Continuity and Disaster Recovery planning.
  • SharePoint
  • Data Loss Prevention (DLP)
  • Data Labeling and Information Rights Management.
  • S/MIMEbased Secure Email.
  • Windows Domains and Active Directory.
  • Identity Access Management (IAM).


Education:

  • Bachelor s or master s degree from an accredited university in IT related discipline


Benefits

Benefits

  • Health and Dental Insurance through Aetna
  • VSP Vision Plan
  • 4 Weeks of Paid Time Off (Vacation Sick Personal Time)
  • 7 Federal Holidays
  • 401K with company match
  • Tuition Reimbursement additional continuing education benefits
  • Employee Referral Bonus
  • Health Savings Account (HSA)
  • Flexible Spending Account (FSA)
  • Short/Long Term Disability
  • Life Insurance Option
  • Pet Insurance
  • Legal Services
  • Identity Theft Protection


Basic Qualifications: 7+ years of demonstrated IT Security engineering work experience providing guidance to project teams. 5+ years of demonstrated TCP/IP network engineering and administration experience. 5+ years of demonstrated Windows / Linux system engineering and administration experience. Demonstrated experience working with secure-SDLC practices in a commercial environment utilizing agile and DevOps models. Demonstrated experience in implementing and maintaining security controls in on-premise and cloud environments. Demonstrated experience performing risk assessments and threat modeling. Demonstrated experience in writing System Security Plans and POAMs. Significant experience in working with ISO 27001/2, NIST 800-171, and NIST 800-53. Demonstrated ability to understand and respond to complex business requirements. Demonstrated ability in strong verbal and written communication skills to interface with technical and business stakeholders. Significant experience working in Jira and Confluence. Be able to pass background investigation to attain and maintain Trusted Role access to company systems. Experience / familiarity with these networking technologies: Key network services including HTTP/SMTP/DNS and supporting technologies including web, domain and mail servers Encryption (IPSec/SSL/TLS) Network Security (e.g. Firewalls, Network Access Controls, Proxies, SPAM/Phishing Prevention, etc) Preferred Qualifications: CISSP and other technical certifications are a plus. Experience with Governance, Risk, and Compliance tools. Cloud computing and architecture. Windows Domains and Active Directory. End-point Protections (HIPS/HIDS). Web Application Programming (Java and related technologies). Knowledge and demonstrated experience designing multi-tier, highly available, multi-threaded, scalable architectures. Secure development frameworks (e.g. OWASP SAMM, Microsoft Security Development Lifecycle, IBM Secure Engineering Framework, etc.) Public Key Infrastructure (PKI) Identity Federation Technologies (SAML, etc.) Business Continuity and Disaster Recovery planning. SharePoint Data Loss Prevention (DLP) Data Labeling and Information Rights Management. S/MIME-based Secure Email. Windows Domains and Active Directory. Identity Access Management (IAM). Education: Bachelor s or master s degree from an accredited university in IT related discipline

Employment Type

Full Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.